Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

CenterPoint Energy data breach confirmed after hacker claims 7.49 million records

The Houston utility says an outsider took customer personal information through an external-facing system; the hacker says a poorly protected public API made it easy.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1CenterPoint Energy disclosed on September 14 that an outsider obtained customer personal information through an external-facing system.
  • 2A hacker claims 7.49 million records were scraped from a public API lacking rate limiting; CenterPoint has not confirmed that figure.
  • 3Proposed class actions had been filed in federal courts by September 15, according to BleepingComputer, while CenterPoint said it does not believe a material financial impact is reasonably likely.

The news

The CenterPoint Energy data breach, disclosed on September 14, exposed personal information of some customers of the Houston-based utility (CNP), after a hacker claimed to have pulled 7.49 million records through a poorly protected public API.

In a Form 8-K filed under Item 8.01, the section for other events, CenterPoint Energy said it learned in September of an online post by a third party claiming to hold a data set of customer information. The company said it activated its incident response protocols, brought in outside cybersecurity experts and informed law enforcement and certain regulators.

The filing states that an unauthorized third party obtained personal information relating to a portion of customers through one of the company's external-facing systems. Electric and gas delivery was not affected. CenterPoint said it does not believe a material impact on its financial condition or results is reasonably likely, and that it expects cybersecurity insurance to offset some incident costs. It plans to notify affected customers and regulators as the law requires.

The attacker, who uses the handle 4d722e4d656f77, told BleepingComputer the data includes names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. The hacker said the records came from cycling through millions of customer IDs on a public CenterPoint API that had no effective rate limiting, meaning no cap on how many requests one client can make, and no web application firewall. Help Net Security reported the attacker also listed email addresses and driver's license numbers. CenterPoint has not confirmed the record count or the fields.

CenterPoint serves about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, according to BleepingComputer, which also reported that the attacker leaked the data after saying the company ignored their messages. Several proposed class actions have been filed in federal court alleging the breach took place between August 17 and September 1. Asked for more detail, the company told Indiana station 14 News that its filing speaks for itself.

The numbers

Records claimed by the attacker (unverified)
7.49 million
CenterPoint metered customers
About 7 million
Breach window alleged in lawsuits
Aug 17 – Sept 1, 2026
Form 8-K filed
Sept 14, 2026

Why CEOs should care

For CISOs and engineering leaders, the claimed method is the lesson. If the attacker's account is accurate, no malware or stolen password was needed, only a public API that answered every request for a customer ID. Ask your teams for an inventory of every customer-facing API that returns personal data, whether record IDs are sequential or guessable, what rate limits and bot controls sit in front of those APIs, and whether anyone would notice millions of lookups spread over days or weeks.

For CFOs and boards, CenterPoint shows that an immateriality finding does not cap legal exposure. The company said that, as of its filing, a material financial effect was not reasonably likely, and it pointed to insurance, yet proposed class actions had been filed in federal courts by September 15, according to BleepingComputer. Finance chiefs should confirm what their cyber policy pays for class-action defense, notification and credit monitoring, and boards should ask who decides how an incident is disclosed and on what evidence.

For buyers of billing, portal and customer-service software, the same question applies to vendors. Ask suppliers that expose your customer data through APIs to show their authentication, rate-limiting and abuse-monitoring controls, and write those expectations into contracts.

The bigger picture

According to BleepingComputer, the attacker says the data was leaked after CenterPoint ignored its messages; the outlet did not report any ransom demand. For utilities, the case also shows that the most immediate cyber risk may sit in customer systems rather than the grid itself. The company stressed that power and gas service never wavered, but the reputational and legal costs attach to the customer data.

The case also shows that disclosure now runs on two tracks: a formal filing that speaks carefully about materiality, and a public narrative shaped by the attacker's posts and by plaintiffs' lawyers. Companies need a communications plan for both, prepared before an incident rather than during one.

What’s next

Watch for CenterPoint's customer notification letters and state regulator filings, which should show how many people the company itself counts as affected, and for any updated SEC filing if its view of the financial impact changes. The federal lawsuits may also be consolidated, which would set the pace for any settlement talks.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

CenterPoint EnergyData breachAPI securityUtilities

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.